<< Prev Question Next Question >>

Question 26/106

SCENARIO
Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.
As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, "I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.
At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. "Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should." Sam said, "I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase." Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"
'I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy." Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. "Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand." Which regulator has jurisdiction over the shop's data management practices?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (106q)
Question 1: Which of the following became a foundation for privacy princ...
Question 2: What is the most important requirement to fulfill when trans...
Question 3: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 4: What was the first privacy framework to be developed?...
Question 5: What term describes two re-identifiable data sets that both ...
Question 6: What is an example of a just-in-time notice?...
Question 7: What is the distinguishing feature of asymmetric encryption?...
Question 8: Which of these actions is NOT generally part of the responsi...
Question 9: Under the Family Educational Rights and Privacy Act (FERPA),...
Question 10: In the realm of artificial intelligence, how has deep learni...
Question 11: SCENARIO Kyle is a new security compliance manager who will ...
Question 12: SCENARIO Wesley Energy has finally made its move, acquiring ...
Question 13: SCENARIO It should be the most secure location housing data ...
Question 14: Which of the following would be the most appropriate solutio...
Question 15: SCENARIO You have just been hired by Ancillary.com, a seller...
Question 16: Which of the following suggests the greatest degree of trans...
Question 17: SCENARIO Looking back at your first two years as the Directo...
1 commentQuestion 18: SCENARIO - Please use the following to answer the next quest...
Question 19: What is a mistake organizations make when establishing priva...
Question 20: What is a main benefit of data aggregation?...
Question 21: Which of the following is a vulnerability of a sensitive bio...
Question 22: Which Organization for Economic Co-operation and Development...
1 commentQuestion 23: What would be an example of an organization transferring the...
Question 24: Which is the most accurate type of biometrics?...
Question 25: When releasing aggregates, what must be performed to magnitu...
Question 26: SCENARIO Carol was a U.S.-based glassmaker who sold her work...
1 commentQuestion 27: Which of the following is an example of the privacy risks as...
Question 28: A user who owns a resource wants to give other individuals a...
Question 29: A vendor has been collecting data under an old contract, not...
Question 30: A user who owns a resource wants to give other individuals a...
Question 31: SCENARIO Kyle is a new security compliance manager who will ...
Question 32: SCENARIO Wesley Energy has finally made its move, acquiring ...
Question 33: What has been found to undermine the public key infrastructu...
Question 34: What is the distinguishing feature of asymmetric encryption?...
Question 35: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 36: Which is NOT a suitable method for assuring the quality of d...
Question 37: SCENARIO - Please use the following to answer the next quest...
Question 38: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 39: If you are asked to advise on privacy concerns regarding pai...
Question 40: What is the distinguishing feature of asymmetric encryption?...
Question 41: SCENARIO - Please use the following to answer the next quest...
Question 42: What is the main reason the Do Not Track (DNT) header is not...
Question 43: Revocation and reissuing of compromised credentials is impos...
Question 44: What privacy risk is NOT mitigated by the use of encrypted c...
Question 45: Revocation and reissuing of compromised credentials is impos...
Question 46: What is the main benefit of using dummy data during software...
Question 47: A privacy engineer has been asked to review an online accoun...
Question 48: SCENARIO - Please use the following to answer the next quest...
Question 49: During a transport layer security (TLS) session, what happen...
Question 50: What is the main reason a company relies on implied consent ...
Question 51: What is the term for information provided to a social networ...
Question 52: What is the main function of the Amnesic Incognito Live Syst...
Question 53: What term describes two re-identifiable data sets that both ...
Question 54: Which technique is most likely to facilitate the deletion of...
Question 55: Which of the following is the least effective privacy preser...
Question 56: What tactic does pharming use to achieve its goal?...
Question 57: Why is first-party web tracking very difficult to prevent?...
Question 58: What must be done to destroy data stored on "write once read...
Question 59: How should the sharing of information within an organization...
Question 60: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 61: SCENARIO - Please use the following to answer the next quest...
Question 62: A sensitive biometrics authentication system is particularly...
Question 63: Which of the following is NOT relevant to a user exercising ...
Question 64: SCENARIO - Please use the following to answer the next quest...
Question 65: A credit card with the last few numbers visible is an exampl...
Question 66: What is the goal of privacy enhancing technologies (PETs) li...
Question 67: How should the sharing of information within an organization...
Question 68: What is a main benefit of data aggregation?...
Question 69: Which of the following entities would most likely be exempt ...
Question 70: In the realm of artificial intelligence, how has deep learni...
Question 71: SCENARIO Looking back at your first two years as the Directo...
Question 72: What is an example of a just-in-time notice?...
Question 73: Which activity would best support the principle of data qual...
Question 74: What is the main reason a company relies on implied consent ...
Question 75: SCENARIO Please use the following to answer the next questio...
Question 76: What is the potential advantage of homomorphic encryption?...
Question 77: When should code audits be concluded?...
Question 78: Aadhaar is a unique-identity number of 12 digits issued to a...
Question 79: SCENARIO - Please use the following to answer the next quest...
Question 80: During a transport layer security (TLS) session, what happen...
Question 81: What is the best way to protect privacy on a geographic info...
Question 82: What would be an example of an organization transferring the...
Question 83: What is the best way to protect privacy on a geographic info...
Question 84: What is the main privacy threat posed by Radio Frequency Ide...
Question 85: Which of the following most embodies the principle of Data P...
Question 86: Which is NOT a suitable action to apply to data when the ret...
Question 87: SCENARIO Please use the following to answer the next questio...
Question 88: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 89: After downloading and loading a mobile app, the user is pres...
Question 90: What has been identified as a significant privacy concern wi...
Question 91: What distinguishes a "smart" device?...
Question 92: SCENARIO It should be the most secure location housing data ...
Question 93: SCENARIO - Please use the following to answer the next quest...
Question 94: SCENARIO Carol was a U.S.-based glassmaker who sold her work...
Question 95: SCENARIO Clean-Q is a company that offers house-hold and off...
Question 96: Which is NOT a way to validate a person's identity?...
Question 97: SCENARIO Wesley Energy has finally made its move, acquiring ...
Question 98: What is the main benefit of using a private cloud?...
Question 99: What is the potential advantage of homomorphic encryption?...
Question 100: SCENARIO You have just been hired by Ancillary.com, a seller...
Question 101: SCENARIO Carol was a U.S.-based glassmaker who sold her work...
Question 102: SCENARIO Please use the following to answer the next questio...
Question 103: Which of the following is considered a records management be...
Question 104: What is the best way to protect privacy on a geographic info...
Question 105: SCENARIO - Please use the following to answer the next quest...
Question 106: What has been found to undermine the public key infrastructu...